Initialization-Key Public Key Exchange Without Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing a secure channel between devices requires secure exchange of public keys, which conventionally involves storing certificates from a certification authority, leading to data storage inefficiencies and complexity.
Innovation Solution
Utilizing an initialization key stored during manufacturing to enable secure exchange of public keys between devices, eliminating the need for certificate storage and simplifying the key exchange process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates from a certification authority are used to establish secure channels, then security is improved, but data storage requirements and device complexity increase
Solution Approach 1:
The patent extracts the certificate authority component from the key exchange process. Instead of relying on third-party certificates, the system uses direct public key exchange between devices, eliminating the need to store and verify certificates while maintaining security through cryptographic protocols
Solution Approach 2:
The patent introduces an intermediary initialization key that is pre-shared between devices during manufacturing. This initialization key acts as a mediator that enables secure public key exchange without requiring certificate authorities, reducing storage requirements while maintaining security
2Reliability
If certificates from a certification authority are used to establish secure channels, then security is improved, but device complexity increases
Solution Approach 1:
The patent removes the certificate verification infrastructure from the device. By using direct public key exchange mediated by an initialization key, the device no longer needs to store certificate authorities, validate certificates, or manage complex trust chains, significantly reducing device complexity
Solution Approach 2:
The patent performs the security setup action in advance during device manufacturing by pre-loading an initialization key. This preliminary action eliminates the need for complex runtime certificate management, reducing operational complexity while maintaining security
3Reliability
If multiple public keys and certificates are stored for chained certificates, then security is improved, but data storage requirements increase
Solution Approach 1:
The patent extracts the entire certificate chain infrastructure from the system. By using a simplified initialization key mechanism, the system eliminates the need to store multiple certificates and public keys associated with chained certificates, dramatically reducing storage requirements
Solution Approach 2:
Instead of the conventional approach where devices store and verify others' certificates, the patent inverts the model by having devices use a pre-shared initialization key to verify each other. This reversal eliminates the need for storing multiple certificates while maintaining security
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods are disclosed for performing a secure exchange of encryption keys (e.g., public keys) between two devices. One or more initialization keys are stored at both devices. In some embodiments, at least one device (e.g., a reader device) stores the initialization key(s) (e.g., a symmetric key, an asymmetric key pair) in local memory as part of performance of a manufacturing process for the device. The second device (e.g., a thin client device) may receive the initialization key(s) from an acceptance cloud (e.g., a server computer configured to perform terminal processing). The initialization key(s) are utilized to perform a secure exchange of the devices' respective public keys. Once these public keys are exchanged, the devices may proceed to establishing a secure connection with which subsequent operations may be performed.